Skip to main content
This page aggregates cross-platform resources to practice JSON Web Tokens (JWT): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 18 challenges across 2 platforms β€” 10 HackTheBox Β· 8 PortSwigger. 10 with a Spanish writeup, 10 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwigger β€” JWT authentication bypass via algorithm confusion (Apprentice) Β· πŸ‡¬πŸ‡§
  2. PortSwigger β€” JWT authentication bypass via algorithm confusion with no exposed key (Apprentice) Β· πŸ‡¬πŸ‡§
  3. PortSwigger β€” JWT authentication bypass via flawed signature verification (Apprentice) Β· πŸ‡¬πŸ‡§
  4. PortSwigger β€” JWT authentication bypass via unverified signature (Apprentice) Β· πŸ‡¬πŸ‡§
  5. HackTheBox β€” Secret (FΓ‘cil) Β· πŸ‡ͺπŸ‡Έ πŸ‡¬πŸ‡§ πŸ“Ή
  6. PortSwigger β€” JWT authentication bypass via jku header injection (Practitioner) Β· πŸ‡¬πŸ‡§

Curated resources

HTB machines practicing JSON Web Tokens (JWT) (10)

PortSwigger labs practicing JSON Web Tokens (JWT) (8)


← Back to the full glossary Last updated: 2026-08-13